* Patches from Caldera, others * Beware the attachment HOROSCOPE.SCR * Blended threats need an intelligent response, exec says, and other interesting reading Today’s bug patches and security alerts:ISS: Flaw in PeopleSoft Application Messaging GatewayAccording to an alert from ISS, “Attackers can use an XML External Entities (XXE) attack to read any file on the vulnerable PeopleSoft application server under the security context of the Web server process. This attack may lead to the exposure of confidential information stored in vulnerable PeopleSoft installations.” The Application Messaging Gateway is configured to run with the PeopleSoft Webserver and is accessible via Java servlet. For more, go to:https://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21811 **********Flaw found in CuteFTP application A buffer overflow vulnerability in CuteFTP’s use of the LIST command could be exploited to run arbitrary code of the affected machine, according to an alert from Secunia. GlobalScape is said to be working on a fix for this problem, which will be posted to:http://www.cuteftp.comSecunia advisory:https://www.secunia.com/advisories/7898/**********Caldera patches wget for OpenLinux As we reported earlier this month, a directory traversal flaw in wget could allow a malicious user to write files outside the download directory of the affected machine. For more, go to:ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-003.0.txt**********More DHCP packages available As we reported late last week, a serious security flaw has been found in the Internet Software Consortium’s Dynamic Host Configuration Protocol that ships with many operating systems. An attacker could exploit this flaw to take control of the affected system. Additional operating system patches are now available:Debian:https://www.debian.org/security/2003/dsa-231OpenPKG:https://www.openpkg.org/security/OpenPKG-SA-2003.002-dhcpd.html**********Today’s roundup of virus alerts:Horo – This e-mail-based virus comes as an attachment called “HOROSCOPE.SCR” in a message entitled “Today’s free horoscope.” The virus writes large amounts of data to the harddrive, which could have an effect on the machine’s performance, and e-mails itself out to everyone listed in a local Outlook address book. (Panda Software)W32/Sahay – Another e-mail worm. This one comes in a message entitled “Fw: Sit back and be surprised…” with an attachment called “MATHMAGIC.SCR”. The malicious code tries to remove another virus from the infected machine and infects all .exe files. It also mails itself out to everyone in the local Outlook address book. (Panda Software, Sophos)Trj/W32.Sevic – A Trojan that blocks access to English versions of Windows. It also displays obscene images on the infected machine. (Panda Software)**********From the interesting reading department:Preventative actionTrend Micro last week unveiled a range of new services and product updates it hopes can help ease the administrative task of preventing and cleaning up after virus outbreaks. Network World, 01/20/03.https://www.nwfusion.com/news/2003/0120trendmicro.htmlBlended threats need an intelligent response, exec saysIT security threats will become more widespread and sophisticated in 2003, and end users will have to lift their game in order to contain those threats, according to Piti Pramotedham, managing director, Asia South, for Computer Associates International. IDG News Service, 01/21/03.https://www.nwfusion.com/news/2003/0121blendthrea.html**********Archives online:If it’s archives you want, we’ve got ’em:https://www.nwfusion.com/newsletters/bug/ Related content news End of road for VMware’s end-user computing and security units: Broadcom Broadcom is refocusing VMWare on creating private and hybrid cloud environments for large enterprises and divesting its non-core assets. By Sam Reynolds Dec 08, 2023 3 mins Mergers and Acquisitions news analysis IBM cloud service aims to deliver secure, multicloud connectivity IBM Hybrid Cloud Mesh is a multicloud networking service that includes IT discovery, security, monitoring and traffic-engineering capabilities. By Michael Cooney Dec 07, 2023 3 mins Network Security Cloud Computing Networking news Gartner: Just 12% of IT infrastructure pros outpace CIO expectations Budget constraints, security concerns, and lack of talent can hamstring infrastructure and operations (I&O) professionals. By Denise Dubie Dec 07, 2023 4 mins Network Security Data Center Industry feature Data centers unprepared for new European energy efficiency regulations Regulatory pressure is driving IT teams to invest in more efficient servers and storage and improve their data-center reporting capabilities. By Maria Korolov Dec 07, 2023 7 mins Enterprise Storage Green IT Servers Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe